TURN Server
The SBN Media TURN server - relays video through firewalls so SBN Video connects on restrictive networks.
TURN Server
The TURN server relays video through firewalls so SBN Video can connect on networks where a direct connection is not possible. It is built into SBN Media and is on by default.
Overview
When a client opens a video stream, SBN Video first tries to connect directly. On restrictive networks a direct path cannot be made, and the video is relayed through a TURN server instead. Because SBN Media includes its own TURN server, this works in most networks without any separate relay software such as coturn.
The TURN server gives each client short-lived credentials automatically while the video session is being set up. You do not normally configure per-client credentials yourself.
- Runs: When configured; at most one per host. It is on by default on a host that serves video.
- Required: Required for video to reach clients across firewalls and NAT. If you choose to use an external TURN server instead, you can turn the built-in one off.
- Depends on: NATS, and being reachable from clients on its control and media ports.
Because clients connect to the TURN server directly, it should sit in the DMZ, alongside the API Proxy.
Configuration
The TURN server is configured under the turnserver namespace. View the defaults with ./sbn-media config eject and set host-specific overrides in sbn-media.local.yaml.
The built-in TURN server is on by default. To use an external TURN server instead, set webrtcpeer.disableInternalTurnServer to true and point WebRTC at the external server.
Setting | Default | Description |
|---|---|---|
| 3478 | The control port clients connect to. |
| 0.0.0.0 | The address to bind to. |
| empty | The address advertised to clients. Defaults to the bind address and port. Set this when the host's public address differs from the address it binds to, so clients are given an address they can actually reach. |
| 1024 | The lowest port used to relay media. |
| 65535 | The highest port used to relay media. |
| 10 | How long a client has to authorize before the attempt times out. |
| empty | Optional fixed username and password per realm, for external or manual use. The built-in server issues per-session credentials automatically and does not need these. |
Example:
For the TURN server to work across a firewall, the control port (3478 by default) and the media relay range must be reachable from clients, and turnserver.publishedURL must advertise an address clients can reach. Because it is contacted directly by clients, the TURN server should sit in the DMZ, alongside the API Proxy.
After changing these settings in sbn-media.local.yaml, reload the configuration for them to take effect. Changing the port or the relay range requires restarting the service.
Firewall
Because the TURN server is exposed in the DMZ, it enforces the built-in SBN Media firewall on the clients that connect to it: it checks the source address of each client and rejects any that the firewall does not allow. The firewall is configured under the separate firewall namespace and is off by default. When enabled it can allow or reject by IP address and by country (using a built-in IP-location database). The same firewall is shared by the other externally-facing SBN Media services.
FAQ
Do I need to install coturn or another TURN server?
No. SBN Media's own TURN server is built in and on by default, and it handles firewall traversal for most networks. Install an external TURN server only if you have a specific reason to, and then turn the built-in one off with webrtcpeer.disableInternalTurnServer.
Video works on the local network but not remotely. What should I check?
Confirm the control port (3478) and the media relay range are open to clients, and that turnserver.publishedURL advertises an address clients can reach - this is the most common cause when the host's public address differs from the address it binds to. If the service will not start, run it in the foreground with sbn-media service exec turnserver -ld to see the error.
How are the TURN credentials managed?
The TURN server issues short-lived credentials to each client automatically as the video session is set up, so there is normally nothing to configure. The turnserver.credentials list is only for fixed credentials used by an external or manual setup.
Can I use an external TURN server instead?
Yes. Set webrtcpeer.disableInternalTurnServer to true and provide the external server's address and credentials in the WebRTC configuration. The built-in TURN server then does not run.
Related pages
- SBN Media Overview (
SBN-Media/overview) - Installing and Configuring SBN Media (
SBN-Media/installation) - API Proxy (
SBN-Media/Platform/api-proxy) - Firewall (
SBN-Media/Configuration/firewall)